U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2019-0034

Change History

CVE Modified by MITRE 4/15/2019 8:31:28 AM

Action Type Old Value New Value
Removed CPE Configuration
OR
     *cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* versions from (including) 16.1 up to (excluding) 16.1r3-s10
     *cpe:2.3:o:juniper:junos:16.1r7-s4:*:*:*:*:*:*:*
     *cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* versions from (including) 17.1 up to (excluding) 17.1r2-s10
     *cpe:2.3:o:juniper:junos:17.1r3:*:*:*:*:*:*:*
     *cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* versions from (including) 17.2 up to (excluding) 17.2r1-s8
     *cpe:2.3:o:juniper:junos:17.2r3-s1:*:*:*:*:*:*:*
     *cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* versions from (including) 17.3 up to (excluding) 17.3r3-s3
     *cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* versions from (including) 17.4 up to (excluding) 17.4r1-s6
     *cpe:2.3:o:juniper:junos:17.4r2-s3:*:*:*:*:*:*:*
     *cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* versions from (including) 18.1 up to (excluding) 18.1r2-s4
     *cpe:2.3:o:juniper:junos:18.1r3-s3:*:*:*:*:*:*:*
     *cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* versions from (including) 18.2 up to (excluding) 18.2r1-s5
     *cpe:2.3:o:juniper:junos:18.2r2-s1:*:*:*:*:*:*:*
     *cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* versions from (including) 18.2x75 up to (excluding) 18.2x75-d40
     *cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* versions from (including) 18.3 up to (excluding) 18.3r1-s2
     *cpe:2.3:o:juniper:junos:18.3r1-s3:*:*:*:*:*:*:*

								
						
Removed CVSS V2
(AV:N/AC:M/Au:N/C:P/I:P/A:N)

								
						
Removed CVSS V3
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

								
						
Removed CWE
CWE-798

								
						
Changed Description
Starting with Junos OS Release 16.1R3, the Junos Telemetry Interface supports Google gRPC remote procedure calls to provision sensors and to subscribe to and receive telemetry data. Configuration files used by gRPC were found to contain hardcoded credentials that could be used by the Junos Network Agent to perform unauthorized read of certain non-critical information (e.g. sensor data). Additionally, APIs exposed via the Juniper Extension Toolkit (JET) may be able to perform non-critical 'set' operations on the device. These APIs need the client to be authenticated for which the username/password can be used. Successful exploitation of this vulnerability can only occur if the Junos Network Agent package (Junos Telemetry Interface) is installed on the device. If the Junos Network Agent is not installed, then the gRPC interface required to leverage these credentials is unavailable and the system is not vulnerable to this issue. Affected releases are Juniper Networks Junos OS: 16.1 versions prior to 16.1R3-S10, 16.1R7-S4; 17.1 versions prior to 17.1R2-S10, 17.1R3; 17.2 versions prior to 17.2R1-S8, 17.2R3-S1; 17.3 versions prior to 17.3R3-S3; 17.4 versions prior to 17.4R1-S6, 17.4R2-S3; 18.1 versions prior to 18.1R2-S4, 18.1R3-S3; 18.2 versions prior to 18.2R1-S5, 18.2R2-S1; 18.2X75 versions prior to 18.2X75-D40; 18.3 versions prior to 18.3R1-S2, 18.3R1-S3. This issue does not affect Junos OS releases prior to 16.1.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a vulnerability. Notes: Google gRPC credentials were found which existed for specific internal product testing purposes which are not used as part of production releases of Junos OS. Hence this is not a vulnerability and this CVE ID assignment has been withdrawn.
Changed Display Vulnerability
true
false
Removed Reference
http://www.securityfocus.com/bid/107877 [No Types Assigned]

								
						
Removed Reference
https://kb.juniper.net/JSA10923 [Vendor Advisory]

								
						
Removed Reference
https://www.juniper.net/documentation/en_US/junos/topics/concept/junos-telemetry-interface-oveview.html [Vendor Advisory]

								
						
Removed Reference
https://www.juniper.net/documentation/en_US/junos/topics/task/configuration/grpc-junos-telemetry-interface-configuring.html [Vendor Advisory]

								
						
Removed Reference
https://www.juniper.net/documentation/en_US/junos/topics/task/installation/network-agent-installing.html [Vendor Advisory]